Someone joins the team and needs to edit a page. The quickest thing is to make them an administrator, so that is what happens. Repeat over a few years and you have eleven administrators, four of whom no longer work there.
WordPress user roles exist precisely to avoid this. The distinction is not bureaucratic — it decides how much damage a single compromised account can do.
The roles, and what they actually mean
Administrator — total control
Can do everything: install and delete plugins and themes, edit code through the dashboard, change any setting, create and delete users, and see all content and data.
Understand what this means in security terms. A compromised administrator account is not a partial breach. It is full control of the site, including the ability to install a backdoor that survives your clean-up.
Editor — all content, no configuration
Can create, edit, publish and delete any post or page, including other people's, and moderate comments. Cannot touch plugins, themes or settings.
This is the right role for most people who "need access to the website". It covers everything a content person actually does.
Author — their own content only
Can write, publish and delete their own posts, and upload media. Cannot touch anyone else's work.
Good for regular contributors you trust to publish without review.
Contributor — write but not publish
Can write and edit their own drafts, but cannot publish them or upload files. Everything goes through review.
The right role for freelancers and guest writers. The inability to upload media is occasionally inconvenient and is deliberate.
Subscriber — read only
Can manage their own profile and nothing else. This is what customers and newsletter signups should be.
WooCommerce roles
Stores add two. Shop Manager can manage products, orders and customers — including customer personal data — without full site control. Customer is a subscriber who can also see their own orders.
Treat Shop Manager as a privileged role. It cannot install plugins, but it can export your entire customer list.
Why this matters more than it sounds
Consider the same attack against two sites.
On the first, the compromised account is an administrator. The attacker installs a plugin containing a backdoor, creates a second admin account for later, edits theme files to inject a redirect, and reads the customer database. Full compromise.
On the second, the compromised account is an editor. The attacker can vandalise content and inject links into posts — bad, visible, and repairable from a backup within an hour. They cannot install anything, cannot create users, and cannot touch the server.
Same attack, same stolen password. The difference in outcome is entirely down to what that account was allowed to do.
This is what least privilege means in practice. It does not prevent the breach; it caps the damage.
The audit worth doing today
Open Users in your dashboard and sort by role. Then ask three questions about every administrator.
Do we know who this is? Accounts nobody recognises are a genuine red flag — creating an innocuous-looking admin account is standard practice after a compromise.
Are they still involved? Former staff, the agency you stopped using, the developer who built the site three years ago. All common, all still holding full control.
Do they need this much? Most administrators would be perfectly served by Editor.
On a typical site this exercise takes ten minutes and removes half the administrator accounts.
Practical rules
- Two administrators is usually right — you and one other, so a lockout is not a crisis
- Give the lowest role that does the job. It is easy to upgrade someone later; it is hard to undo a compromise
- Contractors get time-limited access, removed when the work ends. Put it in the calendar rather than trusting memory
- Do not share accounts. One login per person, so you can tell who did what and remove one person without disrupting everyone
- Two-factor on every privileged account — see our setup guide
- Review quarterly. Put it on your maintenance checklist so it actually happens
The uncomfortable conversation
Reducing someone's access can feel like an accusation. It is worth being direct about why it is not.
This has nothing to do with trust. A trustworthy person with an administrator account and a reused password is a risk, because the risk is not their intentions — it is what happens if their credentials leak from some unrelated service.
Framing it as standard practice rather than a personal judgement usually resolves it. Most people do not want the responsibility of full site control anyway.
Removing someone properly
When an account is no longer needed, deleting it in WordPress is only part of the job.
WordPress asks what to do with their content — attribute it to another user rather than deleting it, unless you genuinely want the posts gone.
Then check the other doors: hosting control panel, FTP, database, domain registrar, Google Analytics and Search Console, and any shared password manager entries. Someone removed from WordPress but still holding FTP access has not really been removed.
Our guide to auditing an inherited website covers the full access checklist.
The signal to watch for
New administrator accounts appearing without explanation is one of the clearest indicators of a compromise. It is also easy to miss, because nobody checks the user list.
Monitoring that alerts on user role changes catches this within minutes rather than whenever someone next happens to look. Our security monitoring service includes it, alongside file integrity and malware scanning.
If your user list has grown beyond anyone's memory
This is extremely common, particularly on sites that have passed between developers or agencies. Nobody can say who half the accounts belong to, and nobody wants to be the one who deletes the wrong thing.
Our WordPress security and error fixing service includes a full access audit — who has what, what they need, and whether any of it looks like it was not created by you.
Get in touch and tell us how many administrators you have. If the answer is "I'm not sure", that is the answer.
Get Shielded
We build, host, secure and monitor business websites — cleaning up hacks and keeping sites online for clients across the UK, USA, Australia and the UAE.